ISO/IEC 20000-1 Certification – IT Service Management Systems

Your practical guide to accredited IT service management certification, trusted by technology teams, clients, and service-driven organisations worldwide.

Delivering IT services consistently and reliably is harder than it looks. ISO/IEC 20000-1 certification demonstrates that your organisation has a structured, independently audited system for planning, delivering, and improving IT services, giving clients, procurement teams, and stakeholders the confidence that your service management is built on a proven international framework, not just internal good practice.

What is ISO/IEC 20000-1?

ISO/IEC 20000-1 is the international standard for IT Service Management Systems (SMS), developed jointly by the International Organization for Standardization and the International Electrotechnical Commission. It defines the requirements for an organisation to establish, implement, maintain, and continually improve a service management system, ensuring IT services are delivered in a planned, controlled, and customer-focused way.

The current version, ISO/IEC 20000-1:2018, was significantly updated to align with the Annex SL framework, bringing it into structural harmony with ISO 9001, ISO 27001, and other major management system standards. This makes it considerably easier to integrate with existing certifications and audit programmes. The 2018 version also introduced a stronger emphasis on service planning, relationship management, and the management of services provided by third parties and customers, reflecting the reality of how modern IT services are actually delivered.

ISO/IEC 20000-1 is closely associated with ITIL, the widely adopted IT service management framework, and organisations already working within ITIL practices will find significant overlap with the standard’s requirements. However, ISO/IEC 20000-1 is an independently certifiable standard, while ITIL is a framework of guidance, and the two serve different but complementary purposes.

The standard applies to any organisation that delivers IT services, whether internally to its own business units or externally to paying customers. This includes managed service providers, IT outsourcing companies, in-house IT departments, cloud service providers, and technology support organisations of every size.

Why Organizations Choose ISO/IEC 20000-1:

Ready to Begin Your ISO/IEC 20000-1 Certification Journey?

Get in touch with Pacific Certifications today for a seamless, transparent path to accredited registration. Our global experts are available 24/7 to support your operational needs.

What framework does ISO/IEC 20000-1 follow?

ISO/IEC 20000-1:2018 is built on the Annex SL framework and follows the PDCA (Plan-Do-Check-Act) cycle as its core operational methodology, consistent with other major ISO management system standards.

ISO-IEC 20000-1 PDCA

Our ISO/IEC 20000-1 Services

From initial scoping to certified status, our auditors bring real IT service management experience to every stage of your certification journey.

Accredited certification

Receive an independently audited, internationally recognised ISO/IEC 20000-1 certificate through a clear, structured two-stage audit process.

Training

Build internal capability across your IT service management and operations teams with training pathways from awareness through to lead auditor level.

Integrated audits

Already certified to ISO 27001 or ISO 9001? We can align audit scheduling and reduce duplication where your systems overlap, making the overall programme more efficient.

Gap analysis

Review your existing IT service management practices internally against ISO/IEC 20000-1 requirements before the formal audit, so your service processes and documentation are ready when it counts.

Key Changes in the Modern IT SMS Framework

ISO/IEC 20000-1 has evolved significantly across its three versions, each reflecting how IT service management expectations have developed in an increasingly complex and interconnected technology environment.

ParameterISO/IEC 20000-1:2005ISO/IEC 20000-1:2011ISO/IEC 20000-1:2018
Structural TemplateStandalone structure aligned with BS 15000.Revised structure with improved clarity but still independent of other ISO frameworks.Annex SL harmonized structure enabling integration with ISO 27001, ISO 9001, and other standards.
Scope of ServicesFocused primarily on internally delivered IT services.Broader applicability to managed service providers and outsourced IT delivery.Explicit requirements for managing services delivered by third parties, partners, and customers.
Risk ApproachLimited risk consideration within service processes.Some risk-based thinking introduced across service planning.Risk-based thinking fully embedded across the SMS, consistent with other Annex SL standards.
LeadershipManagement commitment required but loosely defined.Clearer management responsibility requirements.Direct top management accountability with explicit leadership obligations throughout.
DocumentationPrescriptive documentation requirements.Slightly more flexible documentation approach.Flexible, outcome-focused documentation aligned with organisational context.
Focus AreaProcess compliance and ITIL alignment.Service quality and customer-focused delivery.Continual improvement, third-party service management, and integration with broader governance frameworks.

What are the Principles of ISO/IEC 20000-1?

ISO/IEC 20000-1 is underpinned by a set of service management principles that prioritise structured, customer-focused, and continuously improving IT service delivery.

1. Service Management System

IT services must be managed within a documented, structured system that defines how services are planned, delivered, monitored, and improved, not managed informally or reactively.

2. Customer Focus

Service requirements must be clearly understood, agreed, and met. Customer satisfaction and the effective management of service relationships are central to the standard.

3. Leadership and Commitment

Top management must actively drive the SMS, allocate resources, and take visible accountability for service management performance at an organisational level.

4. Process-Based Approach

Effective IT service delivery depends on defined, interconnected processes covering the full service lifecycle, from design and transition through to delivery, support, and improvement.

5. Risk-Based Thinking

Risks and opportunities affecting service delivery must be identified, assessed, and addressed systematically, including risks associated with third-party and customer-supplied services.

6. Third-Party Management

Where services involve external suppliers, partners, or customer contributions, those relationships must be formally managed with clear agreements, monitoring, and accountability.

7. Continual Improvement

The SMS must drive ongoing improvement in both service performance and the management system itself, using data, audits, and customer feedback as the basis for action.

Clause-wise Structure of ISO/IEC 20000-1

ISO/IEC 20000-1:2018 follows the Annex SL 10-clause framework, with Clauses 4 through 10 defining the formal requirements assessed during certification.

ClauseTitleScope & Requirement Objective
Clause 4Context of the OrganisationIdentify internal and external factors affecting energy performance, understand stakeholder needs, and define the scope of your EnMS.
Clause 5LeadershipTop management must demonstrate commitment, establish an energy policy, and assign clear roles and responsibilities.
Clause 6PlanningConduct an energy review, establish a baseline, identify significant energy uses, and set measurable objectives and targets.
Clause 7SupportEnsure adequate resources, competence, awareness, communication, and control of documented information.
Clause 8OperationPlan and control operations and processes related to significant energy uses, including design and procurement decisions.
Clause 9Performance EvaluationMonitor and measure energy performance against the baseline, conduct internal audits, and carry out management reviews.
Clause 10ImprovementAddress non-conformities, implement corrective actions, and drive continual improvement in energy performance and the EnMS.

Key Service Management Processes within Clause 8

ISO/IEC 20000-1 places particular emphasis on Clause 8, which covers the operational service management processes that define how IT services are actually planned, delivered, and supported. These include:

Process GroupKey Processes
Service PortfolioService catalogue management, service level management.
Relationship and AgreementBusiness relationship management, supplier management, service level agreement management.
SupplyBudget and accounting, capacity and demand, availability, service continuity, information security.
ResolutionIncident management, service request management, problem management.
ControlConfiguration management, change management, release and deployment management.

What are the Requirements of ISO/IEC 20000-1?

ISO/IEC 20000-1 Readiness Guide (Downloads)

Everything you need to prepare for ISO/IEC 20000-1 certification, in one place.

ISO/IEC 20000-1 Audit Checklist

Implementation Guide​

Pre-assessment Template

Application Form​

Steps to Certification

The path to certification balances system building with rigorous auditing.

1. Apply

Submit your application and tell us about your organisation, the scope of IT services covered, and any existing management system certifications.

2. Gap Analysis

Before the formal audit begins, review your existing IT service management processes internally against ISO/IEC 20000-1 requirements to identify and address any gaps.

3. Stage 1 Audit

A documentation review to confirm your SMS, service management processes, and supporting documentation are adequately developed and ready for the main assessment.

4. Stage 2 Audit

Our auditor evaluates whether your SMS is fully implemented and effective across all in-scope service management processes, including incident, change, and supplier management.

5. Certification

Upon successful completion, your ISO/IEC 20000-1 certificate is issued, valid for three years.

6. Surveillance & Recertification

Annual surveillance audits maintain your certification, followed by full recertification at the end of the three-year cycle.

ISO/IEC 20000-1 Certification Timeline

For a standard organisation, the certification process typically follows a ten-week timeline.

WeekActivityCore Milestones & Focus Areas
Week 1Application & ScopingSubmit your application and define the scope of your SMS and the IT services included.
Week 2Gap AnalysisInternally review existing service management processes and documentation against ISO/IEC 20000-1 requirements.
Weeks 3-4SMS ImplementationDeploy or refine service management processes, establish service level agreements, and ensure documented information is in place.
Weeks 5-6Stage 1 AuditOur auditor reviews your SMS documentation and service process documentation to confirm readiness for the main assessment.
Weeks 7-8Stage 2 AuditFull on-site or remote evaluation of your SMS implementation across all in-scope service management processes.
Week 9Technical ReviewAddress any findings, close non-conformities, and finalise the certification review.
Week 10Certificate IssuanceReceive your accredited ISO/IEC 20000-1 certificate upon successful completion of the assessment.

Note: The timeline is indicative and may vary depending on the number of services in scope, organisational complexity, existing process maturity, and completion of any corrective actions required.

What is the ISO/IEC 20000-1 Certification Cost?

ISO/IEC 20000-1 certification costs vary depending on the scope of IT services covered, the size of your organisation, the number of locations involved, and the maturity of your existing service management processes. Organisations integrating ISO/IEC 20000-1 with ISO 27001 or ISO 9001 under a combined audit programme will generally find it more efficient and cost-effective than a standalone assessment.

At Pacific Certifications, we offer transparent, competitive pricing with no hidden charges. Contact us for a tailored quote or use our free cost calculator to get an instant estimate.

Why ISO/IEC 20000-1 Certification is Crucial?

IT services sit at the heart of nearly every organisation, and the expectations placed on service providers have never been higher. As enterprise clients and government procurement bodies are demanding verified evidence that their IT service partners operate within a structured, audited management framework, not just a well-intentioned team with good intentions and an ITIL textbook.

Managed service providers, outsourcing companies, and in-house IT functions that cannot demonstrate ISO/IEC 20000-1 certification are increasingly finding themselves excluded from procurement shortlists before conversations even begin. Certification signals operational maturity, accountability, and a commitment to service quality that clients can rely on and verify independently.

Who Needs ISO/IEC 20000-1 Certification?

Tailored Industry Applications

We provide deep, sector-specific auditing aligned directly with your daily operations.

Professional Training & Competency Courses

Build the internal expertise your organisation needs to implement, maintain, and audit an ISO/IEC 20000-1 compliant service management system.

Lead Auditor Training

For professionals looking to conduct and lead ISO/IEC 20000-1 audits with confidence and internationally recognised credentials.

Lead Implementer Training

For those responsible for designing, implementing, and maintaining an IT Service Management System within their organisation.

Awareness Training

For IT teams and service management professionals who need a clear, practical understanding of ISO/IEC 20000-1 and what it means for how services are planned, delivered, and improved.

Why Work With Pacific Certifications?

We are not just a certification body, we are the partner that helps your organisation earn trust, improve performance, and grow with confidence.

Accredited & Globally Recognised

Accredited by the ABIS (Accreditation Board for International Standards), our certificates are accepted by clients, regulators, and procurement bodies worldwide.

Auditors with Real Industry Experience

Our auditors bring sector-specific knowledge to every engagement, ensuring your audit is relevant, thorough, and conducted by someone who understands your business.

Clients in 150+ Countries

We operate globally with the capability to conduct both remote and on-site audits, delivering consistent, high-quality certification services wherever you are.

Focused on You, Not Just the Process

From your first enquiry to your final certificate, we keep things clear, efficient, and tailored to your organisation — no unnecessary delays, no hidden costs.

Frequently Asked Questions

ISO/IEC 20000-1 certification is independent confirmation that your organisation delivers IT services within a structured, audited management system that meets internationally recognised requirements. For managed service providers and IT teams, it is increasingly the standard clients and procurement bodies look for when assessing whether a service partner can be trusted to deliver reliably and consistently.

ITIL is a framework of best practice guidance for IT service management. ISO/IEC 20000-1 is a certifiable standard that defines what a service management system must achieve. The two are complementary, and organisations already working within ITIL practices will find significant alignment with the standard's requirements, but ITIL adoption alone does not lead to ISO/IEC 20000-1 certification.

Most organisations complete the certification process within 3 to 6 months, depending on the scope of services covered, the maturity of existing processes, and the complexity of the organisation. Our team will provide a realistic timeline from your first conversation with us.

Costs depend on the scope of IT services covered, organisation size, number of locations, and process maturity. Pacific Certifications offers transparent, competitive pricing with no hidden charges. Contact us or use our cost calculator for a tailored estimate.

Certification is voluntary, but it is increasingly a practical requirement in government and enterprise procurement processes for managed service and outsourcing contracts. In the IT services sector, it has moved from being a differentiator to an expected baseline for serious service providers.

Certificates are valid for three years, with annual surveillance audits conducted throughout that period to confirm your SMS remains effective and that service performance continues to meet requirements. A full recertification audit takes place at the end of the three-year cycle.

Yes. Many elements of the SMS audit, including process documentation, service records, and management reviews, can be assessed remotely. Where on-site assessment adds value, particularly for organisations with physical infrastructure or complex multi-location service delivery, our auditors are available to conduct on-site assessments as well.

Yes. ISO/IEC 20000-1:2018 shares the Annex SL common framework with ISO 27001 and ISO 9001, making integration of audits and management systems straightforward. Many IT service organisations hold all three certifications and audit them together in a single, efficient programme.

The scope defines which IT services, locations, and organisational units are covered by the certification. Defining the right scope is an important early step, as it determines what is assessed during the audit and what your certificate covers. Our team will help you think through the right scope from the outset.

If non-conformities are identified during the audit, you will be given a defined timeframe to investigate, correct, and provide evidence of resolution. Our auditors approach every engagement constructively, with the aim of helping your organisation achieve certification, not creating unnecessary obstacles to getting there.

Begin your accredited SMS journey today!

Contact Pacific Certifications at support@pacificcert.com for 24/7 client care, transparent quoting, and comprehensive auditing support.

Get in touch!

Get in touch with us today. Complete the form and we’ll be happy to assist you.


This will close in 20 seconds

Application Form

Free Cost Calculator

Get an instant estimate for certification services. 

Complete the steps below to receive an approximate quotation: